- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Locking out root account - ramifications?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 09:15 AM
07-25-2006 09:15 AM
Locking out root account - ramifications?
I considered locking the root account to only allow console access but I have an ilo board so I can access it from just about anywhere which would sort of defeat the lock it down purpose.
What are some of the dangers/drawbacks to completely locking off access to the root account except through su?
P.S. Thanks in advance for responses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 09:30 AM
07-25-2006 09:30 AM
Re: Locking out root account - ramifications?
In fact I am thinking of making it so no one can log in as root directly and just using sudo to do administrative work.
From my perspective, there are no drawbacks. If you have sudo set up appropriately you will still have all the access you need and never need to actually log in as root.
The security aspect is the big draw. If no one knows the root password, and it is complex enough that it would be difficult to guess, then root has a much smaller chance of being compromised.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 09:33 AM
07-25-2006 09:33 AM
Re: Locking out root account - ramifications?
The implications of this are an improvement in security. This is an approach recommended by HP in its own security courses. There are no dangers in doing this so long as console access is permitted.
I recommend that lan consoles be used so the console can be accessed remotely and people don't have to drive to work to gain emergency access to systems.
I can see no dangers so long as the root password is known to those that need to know it and the console password is not easily guessable.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 09:45 AM
07-25-2006 09:45 AM
Re: Locking out root account - ramifications?
One quick question, in my opinion, locking down root except for console, if you split the hairs, is more secure, yet as long as the console is still available, (which, since i have ilo card, it is just a telnet away) the issue can't be completely resolved. Irrespective of the complexity of the password to the console.
Am I missing something?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 09:55 AM
07-25-2006 09:55 AM
Re: Locking out root account - ramifications?
You are correct to be concerned, but also there is just so much that one can do.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 10:09 AM
07-25-2006 10:09 AM
Re: Locking out root account - ramifications?
Do not lock out the root entirely, leave the console
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 03:33 PM
07-25-2006 03:33 PM
Re: Locking out root account - ramifications?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2006 01:13 AM
07-26-2006 01:13 AM